For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeGCP Professional Cloud ArchitectGCP Professional Cloud Architect Practice Exam 6Question 25
    Medium1 markMultiple Choice
    Subtask 3.1: Security DesignSecurityResource HierarchyOrganization Policy

    GCP PCA · Question 25 · Security Design

    A company is setting up its GCP Organization. They have three main departments: HR, Finance, and Engineering. Engineering has two sub-teams: Dev and QA. They want to apply a policy that prevents the creation of public IP addresses for all Engineering projects, but allows it for HR and Finance. How should you design the resource hierarchy and policy?

    Answer options:

    A.

    Apply the Organization Policy at the Organization node and use IAM to grant exceptions to HR and Finance.

    B.

    Create Folders for HR, Finance, and Engineering. Apply an Organization Policy constraint to the Engineering folder to disable external IPs.

    C.

    Create a custom IAM role that denies public IP creation and assign it to all Engineering users.

    D.

    Apply the constraint individually to every project inside the Engineering department.

    How to approach this question

    Use Folders to group resources and apply Organization Policies at the Folder level for inheritance.

    Full Answer

    B.Create Folders for HR, Finance, and Engineering. Apply an Organization Policy constraint to the Engineering folder to disable external IPs.✓ Correct
    The GCP Resource Hierarchy (Organization -> Folders -> Projects) is designed for policy inheritance. By creating an 'Engineering' folder and applying the `compute.vmExternalIpAccess` constraint there, all child projects (Dev, QA) automatically inherit the restriction.

    Common mistakes

    Confusing IAM roles (identity access) with Organization Policies (resource constraints).
    Question 24All questionsQuestion 26

    Practice the full GCP Professional Cloud Architect Practice Exam 6

    50 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01CASE STUDY: TechStream Gaming Overview: Industry: Gaming Size: 500 employees, $100M revenue Env...MediumQ02CASE STUDY: TechStream Gaming Overview: Industry: Gaming Size: 500 employees, $100M revenue Env...MediumQ03CASE STUDY: TechStream Gaming Overview: Industry: Gaming Size: 500 employees, $100M revenue Env...HardQ04CASE STUDY: TechStream Gaming Overview: Industry: Gaming Size: 500 employees, $100M revenue Env...MediumQ05CASE STUDY: TechStream Gaming Overview: Industry: Gaming Size: 500 employees, $100M revenue Env...Easy
    View all 50 questions →